
CVE-2022-44830 の概念実証エクスプロイト, Sourcecodester Event Registration App v1.0 における CSV インジェクションの脆弱性。ユーザーフィールドに細工された Excel 数式を介したリモートコード実行を実証します。
[推奨される説明] Sourcecodester Event Registration App v1.0 には、First Name、Contact、Remarks フィールドを介した複数の CSV インジェクションの脆弱性が発見されました。これらの脆弱性により、攻撃者は細工された Excel ファイルを介して任意のコードを実行できます。
[追加情報] Proof of Concept: https://drive.google.com/file/d/17rSb8GLFPQfqnVFI56AYffbVMDg8z75t/view?usp=sharing ベンダーホームページ: https://www.sourcecodester.com/javascript/15214/event-registration-app-export-csv-javascript-free-source-code.html ソフトウェアリンク: https://www.sourcecodester.com/sites/default/files/download/oretnom23/registration.zip
[脆弱性タイプ その他] CSV インジェクション
[製品ベンダー] Sourcecodester
[影響を受ける製品コードベース] Event Registration App with Export to CSV in JavaScript - 1.0
[影響を受けるコンポーネント] ソースコード
[攻撃タイプ] リモート
[影響: コード実行] true
[攻撃ベクトル] この脆弱性を悪用するには、攻撃者は First Name、Contact、Remarks フィールドに Excel の数式を挿入し、Save をクリックし、Export to CSV をクリックし、ダウンロードした CSV を Excel で開くと、ペイロードが実行されます。
[参考] https://drive.google.com/file/d/17rSb8GLFPQfqnVFI56AYffbVMDg8z75t/view?usp=sharing https://www.sourcecodester.com/javascript/15214/event-registration-app-export-csv-javascript-free-source-code.html https://www.sourcecodester.com/sites/default/files/download/oretnom23/registration.zip
[発見者] RashidKhan Pathan
CVE-2022-44830 を使用してください。